Thursday, March 28, 2024

500px Hacked – Attackers Stolen 14.8 Million Users Personal Data

500px , an online photography community suffering a massive data breach that leaked 14.8 million users personal information by cybercriminals.

500px global network for photographers and the platform managing around 16 million users who get paid for their work and skills.

Security experts learned this security incident in July 2018 when an
unauthorized party breaking the 500px systems and gained access to users personal information.

In this case, Intruder accessed the user’s sensitive information including
first and last name, username, email address, hashed password, Date of birth, city, state/province, country, and gender.

500px Engineering team already deployed to mitigate this incidents and the company believes that there is no indication of unauthorized access” to user accounts, adding that information like credit card numbers since these data aren’t saved on company server.

The company said that users who have opt-in prior to July 5, 2018, are potential victims of this data breach and the company notify to all users via email as well as onsite and with mobile notifications, however, given the volume of users affected.

According to 500px, following Steps are taken to protect their customer from future attacks.

  • Given the nature of the personal data involved, we have already forced a reset of all MD5-encrypted passwords, and a system-wide password reset is underway.
  • We have vetted access to our servers, databases, and other sensitive data-storage services.
  • We have and are continuing to monitor our source code, both public-facing and internal, to protect against security issues.
  • We are partnering with leading experts in cyber security to further secure our website, mobile apps, internal systems, and security processes.
  • We are modifying our internal software development process.
  • We are continuing to upgrade our network infrastructure.


The company also states that it’s alerted the enforcement and has retained a private security firm to investigate the issue.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

5 Best Workplace Practices To Prevent Data Breach

Houzz Suffers a Data Breach, Alerts Users to Change Password

Airbus Data Breach – Hackers Stolen Employee Sensitive & Personal Data

773 Million Credentials of Email & Password leaked in Massive Data Breach – Biggest Data Dump Ever Found on a Decade

Website

Latest articles

Hackers Actively Exploiting Ray AI Framework Flaw to Hack Thousands of Servers

A critical vulnerability in Ray, an open-source AI framework that is widely utilized across...

Chinese Hackers Attacking Southeast Asian Nations With Malware Packages

Cybersecurity researchers at Unit 42 have uncovered a sophisticated cyberespionage campaign orchestrated by two...

CISA Warns of Hackers Exploiting Microsoft SharePoint Server Vulnerability

Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability in Microsoft...

Microsoft Expands Edge Bounty Program to Include WebView2!

Microsoft announced that Microsoft Edge WebView2 eligibility and specific out-of-scope information are now included...

Beware of Free Android VPN Apps that Turn Your Device into Proxies

Cybersecurity experts have uncovered a cluster of Android VPN applications that covertly transform user...

ZENHAMMER – First Rowhammer Attack Impacting Zen-based AMD Platforms

Despite AMD's growing market share with Zen CPUs, Rowhammer attacks were absent due to...

Airbus to Acquire INFODAS to Strengthen its Cybersecurity Portfolio

Airbus Defence and Space plans to acquire INFODAS, a leading cybersecurity and IT solutions...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles